7.5
CVE-2026-34355
- EPSS 1.12%
- Veröffentlicht 08.06.2026 15:20:30
- Zuletzt bearbeitet 11.08.2026 13:18:29
- CVE-Watchlists
- Unerledigt
Apache HTTP Server: mod_proxy_html buffer overflow
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ HTTP Server Version >= 2.4.0 < 2.4.68
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.12% | 0.628 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
https://httpd.apache.org/security/vulnerabilities_24.html
http://www.openwall.com/lists/oss-security/2026/06/08/6
https://bugzilla.redhat.com/show_bug.cgi?id=2486414
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34355.json
https://access.redhat.com/errata/RHSA-2026:25042
https://access.redhat.com/errata/RHSA-2026:34109
https://access.redhat.com/security/cve/CVE-2026-34355
https://access.redhat.com/errata/RHSA-2026:41906
https://access.redhat.com/errata/RHSA-2026:42828
https://access.redhat.com/errata/RHSA-2026:47046
https://access.redhat.com/errata/RHSA-2026:53371